Privacy Law

Data security – the increasing burden

HomePrivate: BlogLegal insightsData security – the increasing burden

by

reviewed by

Malcolm Burrows

The consequences for an Australian business victim for a breach of cyber security are forecast to exponentially increase. In February 2015 the Parliamentary Joint Committee on Intelligence and Security (Committee) recommended the introduction of mandatory data breach notification scheme (Scheme) by the end of 2015.[1] Whilst the details of the incoming Scheme are currently scant, it is understood that the enacting legislation will have bi-partisan support in federal parliament.

Mandatory data breach notifications requirements a la the Scheme are far from a recent development. They were first recommended by the Australian Law Reform Commission in 2008 and have been in place in the United States since 2003.

Lessons from the United States

Australian businesses have the benefit of approximately fifteen (15) years’ worth of practical guidance from the United States alone. In these fifteen (15) years it is estimated that 675 million data records have been reported as being compromised and 783 data breaches occurred last year alone.[2]

By and large the United States experience demonstrates the significant costs incidental to a data breach that may arise by virtue of mandatory notification schemes. Amongst these costs are the damages to reputation and public relations and the potential litigation commenced by notified parties.

Preparing for the change

Australian businesses should take heed of the United States experience and undertake a comprehensive review of their data breach policies. By ensuring that your policies for reacting to a data breach are airtight you can mitigate any damage that may arise from your obligations under the Scheme. The guidelines for dealing with data breaches released by the Office of the Australian Information Commissioner in 2012 provide a solid foundation (outlined by Dundas Lawyers here) for preparing a policy but you should seek professional advice to develop a policy more tailored to your individual business.

Links and further references

Office of the Australian Information Commissioner, A guide to securing personal information

Office of the Australian Information Commissioner, A guide to data breach preparation and response

Parliamentary Joint Committee on Intelligence and Security, Advisory report on the Telecommunications (Interception and Access) Amendment (Data Retention) Bill 2014

Further information about data security

If you would like further advice on your obligations concerning data breaches please contact us for a confidential and obligation free discussion.

[1] Smith, P, Litigation, PR disasters and higher insurance costs expected from new data breach laws, (2015). Accessed at http://www.afr.com/technology/litigation-pr-disasters-and-higher-insurance-expected-from-new-data-breach-laws-20150805-gis75j accessed on 13 August 2015.

[2] Parliamentary Joint Committee on Intelligence and Security, Advisory report on the Telecommunications (Interception and Access) Amendment (Data Retention) Bill 2014, (2015) at p. 299.


Related insights about data security

  • Australians soon facing age checks when viewing adult websites

    Australians soon facing age checks when viewing adult websites

    On 9 September 2025, the eSafety Commissioner, Mrs Julie Inman Grant (Commissioner), registered six (6) new codes (New Codes) under the Online Safety Act 2021(Cth) (Online Safety Act) aimed at protecting children from the “clear and present” dangers of harmful AI chatbots and other online adult content.  On 9 March 2026, these New Codes will…

    Read more …

  • Ransomware payment reporting obligations

    Ransomware payment reporting obligations

    A “Ransomware Attack” is a cyber security breach in which a malicious actor gains unauthorised access to a computer system or network and then encrypts, exfiltrates, or otherwise compromises data or functionality.[1]  Ransomware Attacks have become increasingly sophisticated, financially motivated, and disruptive across all sectors, prompting legislative intervention to regulate responses and improve national cyber…

    Read more …

  • What is the US Take It Down Act?

    What is the US Take It Down Act?

    The Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (Take It Down Act ) is a United States (US) federal law enacted on 19 May 2025. The Take It Down Act amends 47 U.S. Code § 223 (Code) of the Communications Act 1934 (US) (Communications Act) by establishing new…

    Read more …

  • Federal parliament enacts cyber security legislation

    Federal parliament enacts cyber security legislation

    On 25 November 2024, the Australian Parliament passed a suite of legislation, collectively referred to by the Australian Government as the Cyber Security Legislative Package 2024.  The purported impetus for this legislation was a series of high-profile data breaches in 2022 and 2023.

    Read more …

  • The Digital ID Bill 2023 (Cth) – key points

    The Digital ID Bill 2023 (Cth) – key points

    On 30 November 2023, the Digital ID Bill 2023 (Cth) and the Digital ID (Transitional and Consequential Provisions) Bill 2023 (Digital ID Bills) were introduced in the Australian Senate.  Digital IDs are designed to provide individuals with a convenient way to verify their identity when completing certain online transactions and dealing with government and certain…

    Read more …

  • Misinformation and Disinformation Bill 2023 – draft insights

    Misinformation and Disinformation Bill 2023 – draft insights

    The Communications Legislation Amendment (Combatting Misinformation and Disinformation) Bill 2023 (Cth) (Misinformation Bill) was announced by the Department of Infrastructure, Transport, Regional Development, Communication and the Arts (DITRDCA) in January 2023.  The Misinformation Bill is aimed at restricting the flow of misinformation and disinformation by providing the Australian Communications and Media Authority (ACMA) with increased…

    Read more …

Send this to a friend